[EASI™] External Attack Surface Intelligence, and yes, it is pronounced easy.

0ZONE CHAINimpact: critical
Exposed admin interface chains into database access across the estate.
5 assets · 4 pivotsconfidence: verified
start[subdomain] example.xyz
SQL injection entry (CRITICAL)
→ 1[credential] acquisition.xyz
exposed service_account_key (HIGH)
→ 2[subdomain] api.example.xyz
subdomain takeover pivot
→ 3[admin_panel] admin.acquisition.xyz
exposed admin interface
→ 4[database] db.acquisition.xyz
target: sensitive data store

EXTERNAL ATTACK SURFACE INTELLIGENCE

EXTERNAL ATTACK SURFACE INTELLIGENCE

It’s EASI™.

It’s EASI™.

It’s EASI™.

No noise. Find real exposures within minutes.

No noise. Find real exposures within minutes.

No noise. Find real exposures within minutes.

Start Demo

How it works

External Attack Surface Intelligence – EASI™

External Attack Surface Intelligence – EASI™

Closes the gaps between traditional External Attack Surface Management (EASM), business intelligence, and penetration testing. EASM lists data that is already exposed, using public information. EASI™ designs novel findings, validates them, then tailors the remediation.

Understand our Intelligence Lifecycle

Understand our Intelligence Lifecycle

A full security team's toolkit, in one dashboard.
Each capability below normally means a separate tool with its own copy of the asset list. 0zone runs them all on one live model of your company, so nothing drifts out of sync and every finding is ranked together.
One model of the whole company: every business, subsidiary and acquisition, ranked against each other.
Home−□×
Security overview
12 assets discovered across 3 companies. Example data.
3
Critical
9
High
14
Medium
22
Low
31
Info
Urgent issues
CriticalExposed config file on www.example.com
HighLeaked API key in example-org/example-repo
MediumOutdated library on login.acquisition.com
Riskiest businesses
Example Corp100
Acquisition Inc58
Merger Co44
Get answers in plain English
Portfolio Risk−□×
Portfolio risk
Which of your 3 businesses carries the most risk right now, ranked by a relative Risk Index (open criticality-weighted findings, per-asset density, and how much remains unremediated).
86
Open findings
4
Critical
24
Assets
38%
Remediated (validated)
1. Example CorpRisk Index 100
2. Acquisition IncRisk Index 58
3. Merger CoRisk Index 44
CriticalHighMediumLow
Companies−□×
Companies
Each company is an isolated scope: its assets, findings and repos never mix with a sibling's.
Example Corp12 assets
CriticalHighMedium
Acquisition Inc7 assets
CriticalHighMedium
Merger Co5 assets
HighMedium
Example Corp: example.com, api.example.com, auth.example.com. Subdomains inherit their parent domain's company.
Supply Chain−□×
Supply chain
The vendors your companies depend on, and the vendors those vendors depend on, followed as far as the evidence goes. Third parties are never scanned: everything above your perimeter comes from passive sources.
5 vendors
Example CloudCloud hosting–
cloud.example-vendor.com
observed as DNS, script, CDN
3 companies9 linksdepth 1
Example Corp · 5 linksAcquisition Inc · 3 linksMerger Co · 1 links
Example DNSDNS+
dns.example-vendor.com
observed as DNS
3 companies6 linksdepth 1
Example SSOIdentity+
sso.example-vendor.com
observed as login page, script
2 companies4 linksdepth 1
Example MailEmail+
mail.example-vendor.com
observed as MX, SPF
2 companies3 linksdepth 2
Example CDNCDN+
cdn.example-vendor.com
observed as script
1 companies2 linksdepth 3
Search−□×
Search
Query across all data — assets, DNS records, web pages, and vulnerabilities in one search.
Query?
Assets
0
Web Pages
1
200https://api.example.com/docs
API reference · ...key=AKIAIOSFODNN7EXAMPLE in sample request...
Vulnerabilities
1
HighLeaked AWS access key (AKIA...)
example-org/example-repo · config/prod.js:14
Asset Search−□×
Asset Search
Filter what exists. Dorks (tech:argocd, port:3389, service:rdp, waf:cloudflare) seed the same filters.
6 assets
Active scan runs only on authorized, non-fronted hosts.
Technology
nginx10
react10
cloudflare20
Service
https10
ssh6
smtp8
Port
4436
804
224
WAF / edge
cloudflare20
none8
www.example.comDomainready
api.example.comDomainready
auth.example.comDomainready
login.acquisition.comDomainready
mail.merger.comDomainready
staging.merger.comDomainready
Assets−□×
Assets
Add a domain or IP; 0zone discovers subdomains and resolves each asset.
Add Assets
Asset
DNS
Status
Actions
www.example.comA 93.184.216.34Done
api.example.comA 93.184.216.34Done
mail.merger.comA 93.184.216.34Done
Findings−□×
Findings
Vulnerability scanner and findings browser.
3 Critical
9 High
14 Medium
22 Low
31 Info
CriticalExposed .env filewww.example.com
exposed-env-file · Template matched on GET /.env; response contains DB_PASSWORD. Example data.
HighOutdated library with known CVElogin.acquisition.com
HighLeaked API key in repositoryexample-org/example-repo
MediumMissing HSTS headerstaging.merger.com
Reports−□×
Reports
3 reports
PATTERNHighConfiguration exposure
www.example.com
CHAINCriticalLogin pivot to internal admin
login.acquisition.com
PATTERNLowDebug endpoint enabled
staging.merger.com
Jobs−□×
Jobs
2 running, 2 queued. Capacity 1.6 of 2 vCPU.
Asset
Kind
Status
Progress
www.example.comnucleirunning
api.example.comcrawlrunning
mail.merger.comsubdomainqueued
login.acquisition.comtriagequeued
staging.merger.comportscandone
auth.example.comscreenshotdone
Web Scraper−□×
Web Scraper
412
Pages crawled
6
Unique hosts
14
Forms
5
Max depth
3
HTTP errors
0.8s
Avg load
URL
Status
Title
Detected
https://example.com/login200Sign inform: password
https://api.example.com/docs200API referencereact, nginx
https://staging.merger.com/debug403Forbidden—
Attack Graph−□×
Attack Graph
callscontainssigns in totrustsSSO toreachesowned byowned bywww.example.comapi.example.comexample-org/example-repoAWS access keyauth.example.comlogin.acquisition.comstaging.merger.comExample Corp
HostSecretCompanySeverity halo
Path: repo secret to company
4 hops · entry: committed secret · impact: company data store
1example-org/example-repo
2AWS access key
3auth.example.com
4login.acquisition.com
5Example Corp
ATT&CK: T1552.001 Credentials in Files
Known Chains−□×
Known chains
Multi-step attack chains. Mark a chain confirmed once it is reproduced end to end.
CriticalLeaked key to cloud admin
Secret in repo→Cloud API auth→Storage read
HighSubdomain takeover to session theft
Dangling CNAME→Takeover→Cookie scope
MediumDebug endpoint to internal pivot
/debug exposed→Env disclosure→Internal host
Code Security−□×
Code Security
3 connections
Add repository connection
Repository
Company
Source
Findings
example-org/example-repoExample Corpsource: discoveryHigh 4
acq-inc/web-portalAcquisition Incsource: manualMedium 2
Secrets and findings surface only under the company that owns the repo.
SaaS Matrix−□×
SaaS Attack Matrix catalogue
Techniques, vendors and the attack paths that connect them.
OAuth consent phishingInitial accessIdentity
Token theft via browserCredential accessSSO
Webhook hijackPersistenceCI/CD
Shadow admin grantPriv-escIdentity
Typosquatting−□×
Typosquatting & Domain Protection
Brand impersonation surface for Example Corp. Auto-rescans daily; manual rescan refreshes everything below.
Total permutations
1,248
Active threats
7
High-risk MX servers
2
Defensive opportunities
36
Candidate
Strategy
Reg
MX
HTTP
Server / Registrar
Risk
examp1e.comhomoglyphyesyes200nginx / Example RegistrarCritical
example-login.comadditionyesyes200Apache / Example RegistrarHigh
exampel.comtranspositionyes—301— / Example RegistrarMedium
examplle.netrepetitionyes—parked— / Example RegistrarLow
Home
Security overview: severity strip, riskiest businesses, urgent issues, and plain-English questions.
Portfolio Risk
Rank every business you track by a relative Risk Index, with severity mix and remediation.
Companies
Every company, subsidiary and acquisition as its own isolated scope.
Supply Chain
Ranked vendors, how deep each sits in your chain, and a layered dependency graph. Passive only.
Search
One query across assets, DNS, web pages and vulnerabilities. Dorks, regex, exact word.
Asset Search
Filter assets by technology, service, port and WAF, or seed filters with dorks.
Assets
Add assets, then watch DNS, HTTP, screenshots and WAF/CDN detection resolve.
Findings
One triage view for scanner, secrets, code risks, passive and repo findings.
Reports
Reproduction, impact against your threat model, and mitigation, ready to export.
Jobs
Every scan and crawl in flight, with queue and capacity control.
Web Scraper
Crawl a site, then dork the corpus for secrets, forms and technologies.
Attack Graph
Explore paths from an entry point to impact; time travel and what-if.
Known Chains
Confirmed multi-step chains, verified end to end with evidence.
Code Security
Connect GitHub and GitLab, then triage code and secret risks per company.
SaaS Matrix
The SaaS attack catalogue: techniques, vendors and paths.
Typosquatting
Lookalike domains, risk-scored, with evidence and draft notices for you to act on.